Proposal: Discourage rpmbuild --sign

Karl DeBisschop kdebisschop at alert.infoplease.com
Thu Jan 1 14:00:09 UTC 2004


On Thu, 2004-01-01 at 02:43, Michael Schwendt wrote:
> On Wed, 31 Dec 2003 17:24:23 +0000, Rui Miguel Seabra wrote:
> 
> > > On Wed, 31 Dec 2003 02:42:28 -1000, Warren Togami wrote:
> > > > Proposal
> > > > ========
> > > > rpm-4.2.2 in rawhide and all future versions should discourage the use 
> > > > of rpmbuild --sign.  Perhaps this can be done effectively by adding a 
> > > > large and annoying warning message and 15 second delay.  Or disable it 
> > > > completely.  I don't care how, just discouragement should be done.
>
> Also think about developers who build rpms of their own software.  They
> wouldn't like an "annoying warning message and a 15 second delay".

You might get nearly the same effectiveness over the long-term if you
just put the message as the first and last thing output by rpmbuild,
that way people building interactively will see the note and URL when
the build finishes, and people running automated builds will see the
same in their log file when they first bring it up in less or view or
whatever.

In the long run, I think you can count on most developers to try to do
the right thing if they are told what it is, and to read their build
logs. Maybe not immediately, but why be annoying about it right from the
start?

-- 
Karl DeBisschop <kdebisschop at alert.infoplease.com>





More information about the fedora-devel-list mailing list